Presentation by Computer Forensics NZ Ltd for Auckland University SC CF NZ OUR PRIME OBJECTIVE: To successfully recover lost, damaged, hidden or deleted files from a computer system after an accidental, deliberate or malicious action. COMPUTER FORENSICS NZ LTD
Presentation by Computer Forensics NZ Ltd for Auckland University SC What is computer forensics? Disk operating system considerations. How data is recovered. What to do when data can’t be recovered, and how to prevent recovery. Commercial and paralegal aspects. The process. Q & A. THIS PRESENTATION
Presentation by Computer Forensics NZ Ltd for Auckland University SC WHAT IS COMPUTER FORENSICS Computer Forensics is the acquisition, preservation, preparation, analysis and presentation of computer-related evidence utilising secure, controlled methodologies and auditable procedures.
Presentation by Computer Forensics NZ Ltd for Auckland University SC THE FATHER OF FORENSICS “For any two points of contact there is always a cross-transference of material from one to the other.” Edmond Locard Every contact leaves a trace.
Presentation by Computer Forensics NZ Ltd for Auckland University SC MODERN PERSPECTIVE For ever interaction with a PC there will always be material left behind on that PC OR
Presentation by Computer Forensics NZ Ltd for Auckland University SC EVERY INTERACTION WITH A PC LEAVES TRACE DATA BEHIND MODERN PERSPECTIVE #2
Presentation by Computer Forensics NZ Ltd for Auckland University SC Master Boot Record. Partition table. File Allocation Table. Data storage area. GENERIC DISK OS
Presentation by Computer Forensics NZ Ltd for Auckland University SC Reference only is deleted Space is flagged as available for re use. FDISK and FORMAT Urban myths WHEN DELETE IS NOT DELETE
Presentation by Computer Forensics NZ Ltd for Auckland University SC Full files. ASCII text. Graphics. WHAT INFO CAN BE RECOVERED
Presentation by Computer Forensics NZ Ltd for Auckland University SC When the hard disc platter has been: Badly distorted by fire. Significant physical damage. Subjected to abnormally high magnetic fields. WHEN IS THERE PROBABLY NO CHANCE
Presentation by Computer Forensics NZ Ltd for Auckland University SC Overwrite all sectors. Once, many times. Protect from whom. Ultimate protection. PROTECT AGAINST DATA RECOVERY??
Presentation by Computer Forensics NZ Ltd for Auckland University SC Case 1 – Avco. Case 2 – Government departments. Happens every day every where. DON’T GIVE THE COMPANY’S SECRETS AWAY
Presentation by Computer Forensics NZ Ltd for Auckland University SC Main Causes: Accidental delete. Advised to reformat by IT advisor. Partition table corrupt. Disk hardware failure. Malicious damage. Viral contamination. COMMERCIAL DATA RECOVERY
Presentation by Computer Forensics NZ Ltd for Auckland University SC Unintended left evidence. High usage of PCs at home. Private use of company PC. Files on archival backups. Electronic media discovery. PARALEGAL DATA RECOVERY
Presentation by Computer Forensics NZ Ltd for Auckland University SC Cases: Professional practice 2 years ago. Ex-employee using company data. Senior manager and PA setting up competitive company. PARALEGAL DATA RECOVERY #2
Presentation by Computer Forensics NZ Ltd for Auckland University SC Similar for data recovery and paralegal: Acquire. Preserve. Prepare. Analyse. Present. THE RECOVERY PROCESS
Presentation by Computer Forensics NZ Ltd for Auckland University SC Three key points to leave with you. Data is rarely completely deleted from a hard disk. Implications for commercial security. Implications for prosecution and defence in court. RECAP
Presentation by Computer Forensics NZ Ltd for Auckland University SC Paralegal com/subjects.html General Data Recovery privacy.htm SUGGESTED SURFING
Presentation by Computer Forensics NZ Ltd for Auckland University SC YOUR TURN Q & A TIME